Southperry.net
People being hacked since the last Server Check. - Printable Version

+- Southperry.net (https://www.southperry.net)
+-- Forum: Maplestory (https://www.southperry.net/forumdisplay.php?fid=15)
+--- Forum: Maplestory Discussion (https://www.southperry.net/forumdisplay.php?fid=31)
+--- Thread: People being hacked since the last Server Check. (/showthread.php?tid=46631)



People being hacked since the last Server Check. - Locked - 2011-09-05

Viaje Wrote:Curious what you mean about Gamelauncher though. I'm able to type in more than 12 characters, and there doesn't seem to be any indication that that's an invalid length.

Last time I checked, it was 12 characters. I tried a 64-digit and it didn't fit, so I'm sure 64 digit works for what I mentioned.

Kalovale Wrote:The site is never up when I need to update my password.

The log-in page now allows 30 characters, it seems.

Ah, that makes sense.


People being hacked since the last Server Check. - Yukiko - 2011-09-05

Locked Wrote:Last time I checked, it was 12 characters. I tried a 64-digit and it didn't fit, so I'm sure 64 digit works for what I mentioned.

With one of the recent server maintenances, they updated it so that more than 12 characters can be entered into Game Launcher.


People being hacked since the last Server Check. - Viaje - 2011-09-05

Bomber Wrote:I'm just not going to pay any attention to these "hacked" accounts because I'd rather go on oblivious then worry about it...
Except you aren't oblivious, nor are you trying to remain so. The simple fact that you continue to read this thread speaks as much.
What you're experiencing is something else entirely.

Locked Wrote:Last time I checked, it was 12 characters. I tried a 64-digit and it didn't fit, so I'm sure 64 digit works for what I mentioned.
I'm still not sure how that protects your account at all as it's unlikely that Gamelauncher is being used by these hackers at all.


People being hacked since the last Server Check. - Bomber - 2011-09-05

Viaje Wrote:Except you aren't oblivious, nor are you trying to remain so. The simple fact that you continue to read this thread speaks as much.
What you're experiencing is something else entirely.
I know this is happening.
I know that these hackings are happening to basilers
I know these hackings are happening in SP.
I'm not letting this hacking stop me from doing my day normally. I'd rather pretend these hackings didn't happen. The simple fact that I understand this shows I'm not in denial. But in practice I'm in denial. That's like saying people pretend the holocaust never happened and are fully aware it did. Most people with that actually believe there was no holocaust because they are mentally unable to accept that it did happen.


People being hacked since the last Server Check. - Muppy - 2011-09-05

Guess my nights of afking in CS won't end anytime soon. Rolleyes


People being hacked since the last Server Check. - Nikkey - 2011-09-05

Viaje Wrote:I read through Nexon's "venting" thread and at least two people reported that Nexon removed the feature that locks you out of your account after too many failed password attempts, allowing hackers to potentially brute-force people's passwords.

Assuming a 50 msec delay (which is quite optimistic I think) would make it possible to brute force a 6-symbol password in 582 years, so I have my doubts that this is the approach they're going for here. Dictionary attacks also seem out of the question. If anything, it's either a possibility to logon using some obscure vulnerability with the game (man in the middle in front of the server in front of a non-SSL'd transmission or some issue with login in the game itself) or a database leak of poorly secured passwords.


People being hacked since the last Server Check. - Locked - 2011-09-05

Viaje Wrote:I'm still not sure how that protects your account at all as it's unlikely that Gamelauncher is being used by these hackers at all.

Based on what I know, the hacker here in Windia who matches these stories seems to do this:
-Run multiple clients.
-Leave everything untradeable, untouched
-Smega "18-1 shopping gogogogogogo", in a similar fashion of the smegas of kMS
-Sells these items really cheap.

If the first thing is true (Which it is), you can't multi client without GameLauncher.


People being hacked since the last Server Check. - Viaje - 2011-09-05

Devil's Sunrise Wrote:Assuming a 50 msec delay (which is quite optimistic I think) would make it possible to brute force a 6-symbol password in 582 years, so I have my doubts that this is the approach they're going for here.
I'm going to assume that's taking a character-by-character approach, testing every possible combination (since I don't know the formulas off the top of my head, I have no way of reversing your math to know for sure).
Thing is, that's one of the most inefficient ways to brute-force an account because real humans rarely have passwords such as 4%.sS! but tend to swerve more towards things like c0w123.

Unless we have everyone who has been hacked so far step forward and tell us what their passwords were when they were hacked, we have no way of knowing how complex their passwords were and, by extension, no idea how difficult they would be to brute-force.

My brother's, for example, was absolutely pitiful and I'm quite embarrassed by it.
He just figured his ID and PIC were plenty of security so he didn't take much effort when it came to creating his password.

Locked Wrote:Based on what I know, the hacker here in Windia who matches these stories seems to do this:
-Run multiple clients.
-Leave everything untradeable, untouched
-Smega "18-1 shopping gogogogogogo", in a similar fashion of the smegas of kMS
-Sells these items really cheap.

If the first thing is true (Which it is), you can't multi client without GameLauncher.
I didn't know multiclient was back at all.

But you could definitely be logged into two different accounts with two different machines.
I do it quite often.


People being hacked since the last Server Check. - Eos - 2011-09-05

Viaje Wrote:I'm still not sure how that protects your account at all as it's unlikely that Gamelauncher is being used by these hackers at all.

You do realize they can run a packet editor script whether they've activated the game via the launcher or the website with the same effects?
The assumption they're using the site to bruteforce is predicated on flawed logic.

The bruteforce idea itself is unlikely, period. It's far more likely to be yet another gap in the security between the (minimum) of three servers you have to pass through to login.


People being hacked since the last Server Check. - Locked - 2011-09-05

The hacker here runs two machines with around 12 clients each judging from how many stores he puts up with the same title full of hacked equips.
Multi maple is a "VIP hack" that is supposedly "exclusive and private"


People being hacked since the last Server Check. - Viaje - 2011-09-05

Eos Wrote:You do realize they can run a packet editor script whether they've activated the game via the launcher or the website with the same effects?
The assumption they're using the site to bruteforce is predicated on flawed logic.
My assumption was only that any limitations presented by the Gamelauncher would not be a limitation at all, a fact which you have so graciously just proven for me. Thank you very much.

Eos Wrote:The bruteforce idea itself is unlikely, period. It's far more likely to be yet another gap in the security between the (minimum) of three servers you have to pass through to login.
If there's a security gap, then it would reason that more people would be affected at a faster rate.
What makes you believe that a breach is more likely?

Keep in mind that I never indicated that one possibility was more likely than another.
I'm not quite that bold or smug.


People being hacked since the last Server Check. - Dark Zero - 2011-09-05

Locked Wrote:Based on what I know, the hacker here in Windia who matches these stories seems to do this:
-Run multiple clients.
-Leave everything untradeable, untouched
-Smega "18-1 shopping gogogogogogo", in a similar fashion of the smegas of kMS
-Sells these items really cheap.

If the first thing is true (Which it is), you can't multi client without GameLauncher.

some premium hackers can do it lol... but almost they don't have any GM powers...


People being hacked since the last Server Check. - Eos - 2011-09-05

Viaje Wrote:If there's a security gap, then it would reason that more people would be affected at a faster rate.

The rate is limited by several factors;
The # of people who are aware of the exploit (and more importantly the # of people who actually know how to do the exploit), the difficulty/time constraints/requirements to use the exploit, and the number of simultaneous exploits each person who knows how to do it can perform.

It's impossible to get a true idea of the potential rate of the breaching without knowing those factors and it's equally impossible for us to gauge how fast they're moving based on existing breaches because we don't know how many people have been hit, how many of them were via the same vector, or exactly when they occurred.

Only whomever is actually doing it can tell us the limits.


People being hacked since the last Server Check. - Takebacker - 2011-09-05

I reset my pic without the ability to actually log on and change it so if anyone is going to hack my account, go right the f'uck ahead. This happens every time and i never do s'hit and always come out with my stuff. All this FUD doesn't help anyone.


People being hacked since the last Server Check. - Flonne - 2011-09-05

Eos Wrote:The rate is limited by several factors;
The # of people who are aware of the exploit (and more importantly the # of people who actually know how to do the exploit), the difficulty/time constraints/requirements to use the exploit, and the number of simultaneous exploits each person who knows how to do it can perform.

It's impossible to get a true idea of the potential rate of the breaching without knowing those factors and it's equally impossible for us to gauge how fast they're moving based on existing breaches because we don't know how many people have been hit, how many of them were via the same vector, or exactly when they occurred.

Only whomever is actually doing it can tell us the limits.
Also, they may be slowing down just to keep the number of hackings within "reasonable error margins" so nothing is done about it.

Based on what the guy who changes his pass every 2 weeks said earlier, I somehow doubt it was a one-time dB exploit at this point, sadly.


People being hacked since the last Server Check. - Eos - 2011-09-05

Flonne Wrote:Also, they may be slowing down just to keep the number of hackings within "reasonable error margins" so nothing is done about it.

Also possible. Artificial/self-imposed limits are another of the many variables.


People being hacked since the last Server Check. - ResistGreen - 2011-09-05

Just curious, To those who got hacked, what email provider did you guys use?


People being hacked since the last Server Check. - Eos - 2011-09-05

ResistGreen Wrote:Just curious, To those who got hacked, what email provider did you guys use?

We've already covered they were using a wide variety of different ones, some of which no longer even exist.


People being hacked since the last Server Check. - ResistGreen - 2011-09-05

Eos Wrote:We've already covered they were using a wide variety of different ones, some of which no longer even exist.

Oh oops, Didn't catch that.


People being hacked since the last Server Check. - Eos - 2011-09-05

ResistGreen Wrote:Oh oops, Didn't catch that.

It's one of the first things that gets asked, every single time one of these occurs; everyone expects to be able to blame some one.